I will security test your ai app, llm chatbot or agents
Web App and API Penetration Tester with Published CVEs
About this Gig
Shipping an AI feature, chatbot, or agent? It's a whole new attack surface, and most
testers don't know how to poke at it. Prompt injection, leaked system prompts, agents
tricked into running unsafe tools, data and API keys leaking out. A normal web pentest
misses all of it.
I do this for a living. I've built production LLM agent pipelines and I break them too,
so I know where they fall over. I pair that with real app-security depth: a High-severity
OIDC flaw in better-auth at CVSS 8.7, a published CVE in n8n, and a spot on SAP's Security
Hall of Fame.
What you get: testing mapped to the OWASP Top 10 for LLM apps, a severity-rated report
with working proof-of-concepts, clear fixes, and a free re-test.
Tell me what your AI app does and your stack, and I'll scope it for you.
My Portfolio
FAQ
What kinds of issues do you actually test for?
Prompt injection (direct and indirect), jailbreaks, system-prompt leakage, unsafe tool and function calls, data and PII exposure, plus the normal auth and API layer underneath.
Do you test the app behind the AI too?
On Standard and Premium, yes. A lot of "AI" incidents are really plain web/API bugs.
Can you help fix what you find?
Yes. I'm also a developer, so the report has fixes your team can act on, not just scary screenshots.

